GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,801
Erlang
36
GitHub Actions
29
Go
2,382
Maven
5,000+
npm
4,011
NuGet
720
pip
3,810
Pub
12
RubyGems
930
Rust
987
Swift
38
Unreviewed advisories
All unreviewed
5,000+
314 advisories
Filter by severity
Jenkins Repository Connector Plugin has insufficiently protected credentials
Low
CVE-2019-1003038
was published
for
org.jenkins-ci.plugins:repository-connector
(Maven)
May 13, 2022
Jenkins PRQA Plugin stored password in plain text
Low
CVE-2019-1003048
was published
for
com.programmingresearch:prqa-plugin
(Maven)
May 13, 2022
Jenkins Octopus Deploy Plugin stores credentials in plain text
Low
CVE-2019-1003071
was published
for
hudson.plugins.octopusdeploy:octopusdeploy
(Maven)
May 13, 2022
Jenkins Audit to Database Plugin stores credentials in plain text
Low
CVE-2019-1003075
was published
for
org.jenkins-ci.plugins:audit2db
(Maven)
May 13, 2022
Jenkins hyper.sh Commons Plugin stores credentials in plain text
Low
CVE-2019-1003074
was published
for
sh.hyper.plugins:hyper-commons
(Maven)
May 13, 2022
Jenkins AWS CloudWatch Logs Publisher Plugin stores credentials in plain text
Low
CVE-2019-1003062
was published
for
org.jenkins-ci.plugins:aws-cloudwatch-logs-publisher
(Maven)
May 13, 2022
Jenkins Bugzilla Plugin stores credentials in plain text
Low
CVE-2019-1003066
was published
for
org.jvnet.hudson.plugins:bugzilla
(Maven)
May 13, 2022
Jenkins CloudShare Docker-Machine Plugin stores credentials in plain text
Low
CVE-2019-1003065
was published
for
org.jenkins-ci.plugins:cloudshare-docker
(Maven)
May 13, 2022
Jenkins FTP publisher Plugin stores credentials in plain text
Low
CVE-2019-1003055
was published
for
org.jvnet.hudson.plugins:ftppublisher
(Maven)
May 13, 2022
Jenkins veracode-scanner Plugin stores credentials in plain text
Low
CVE-2019-1003070
was published
for
org.jenkins-ci.plugins:veracode-scanner
(Maven)
May 13, 2022
Jenkins aws-device-farm Plugin stores credentials in plain text
Low
CVE-2019-1003064
was published
for
org.jenkins-ci.plugins:aws-device-farm
(Maven)
May 13, 2022
Jenkins Amazon SNS Build Notifier Plugin stores credentials in plain text
Low
CVE-2019-1003063
was published
for
org.jenkins-ci.plugins:snsnotify
(Maven)
May 13, 2022
Jenkins Aqua Security Scanner Plugin stores credentials in plain text
Low
CVE-2019-1003069
was published
for
org.jenkins-ci.plugins:aqua-security-scanner
(Maven)
May 13, 2022
Jenkins OWASP ZAP Plugin stores unencrypted credentials
Low
CVE-2019-1003060
was published
for
org.jenkins-ci.plugins:zap
(Maven)
May 13, 2022
Jenkins Bitbucket Approve Plugin stores credentials in plain text
Low
CVE-2019-1003057
was published
for
org.jenkins-ci.plugins:bitbucket-approve
(Maven)
May 13, 2022
Jenkins IRC Plugin stores credentials in plain text
Low
CVE-2019-1003051
was published
for
org.jvnet.hudson.plugins:ircbot
(Maven)
May 13, 2022
Jenkins AWS Elastic Beanstalk Publisher Plugin stores credentials in plain text
Low
CVE-2019-1003052
was published
for
org.jenkins-ci.plugins:aws-beanstalk-publisher-plugin
(Maven)
May 13, 2022
Jenkins Vulnerable to Cross-Site Request Forgery (CSRF) Attack
Low
CVE-2015-5318
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 13, 2022
Jenkins allows Cross-Site Scripting (XSS)
Low
CVE-2015-5326
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 13, 2022
Exposure of Sensitive Information to an Unauthorized Actor in Jenkins-mailer-plugin
Low
CVE-2017-2651
was published
for
org.jenkins-ci.plugins:mailer
(Maven)
May 13, 2022
Exposure of Sensitive Information to an Unauthorized Actor in Jenkins
Low
CVE-2017-2603
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 13, 2022
JBossWS vulnerable to uncontrolled recursion
Low
CVE-2011-1483
was published
for
org.jboss.ws:jbossws-common
(Maven)
May 13, 2022
Nimbus JOSE+JWT vulnerable to padding oracle attack
Low
CVE-2017-12973
was published
for
com.nimbusds:nimbus-jose-jwt
(Maven)
May 13, 2022
Exposure of Sensitive Information to an Unauthorized Actor in Oracle MySQL Connectors Java
Low
CVE-2017-3589
was published
for
mysql:mysql-connector-java
(Maven)
May 13, 2022
Jenkins Coverity Plugin has Insufficiently Protected Credentials
Low
CVE-2018-1000104
was published
for
org.jenkins-ci.plugins:coverity
(Maven)
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API